Search CVE reports


Toggle filters

1 – 10 of 27 results


CVE-2025-58190

Medium priority
Needs evaluation

The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

7 affected packages

golang-golang-x-net, google-guest-agent, containerd, golang-golang-x-net-dev, adsys...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-golang-x-net Needs evaluation Needs evaluation
google-guest-agent Needs evaluation Needs evaluation Needs evaluation Needs evaluation
containerd Needs evaluation Needs evaluation Needs evaluation Needs evaluation
golang-golang-x-net-dev Not in release Not in release Needs evaluation Needs evaluation
adsys Needs evaluation Needs evaluation Needs evaluation
juju-core Not in release Not in release
lxd Not in release Not in release Needs evaluation Needs evaluation
Show all 7 packages Show less packages

CVE-2025-47911

Medium priority
Needs evaluation

The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

7 affected packages

golang-golang-x-net, google-guest-agent, containerd, golang-golang-x-net-dev, adsys...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-golang-x-net Needs evaluation Needs evaluation
google-guest-agent Needs evaluation Needs evaluation Needs evaluation Needs evaluation
containerd Needs evaluation Needs evaluation Needs evaluation Needs evaluation
golang-golang-x-net-dev Not in release Not in release Needs evaluation Needs evaluation
adsys Needs evaluation Needs evaluation Needs evaluation
juju-core Not in release Not in release
lxd Not in release Not in release Needs evaluation Needs evaluation
Show all 7 packages Show less packages

CVE-2025-64329

Medium priority

Some fixes available 10 of 12

containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4, and 2.2.0-beta.0 through 2.2.0-rc.1 contain a bug in the CRI Attach implementation where a user can...

2 affected packages

containerd, containerd-app

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
containerd Fixed Fixed Fixed Fixed
containerd-app Fixed Fixed Fixed
Show less packages

CVE-2024-25621

Medium priority

Some fixes available 10 of 12

containerd is an open-source container runtime. Versions 0.1.0 through 1.7.28, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 through 2.1.4 and 2.2.0-beta.0 through 2.2.0-rc.1 have an overly broad default permission vulnerability....

2 affected packages

containerd, containerd-app

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
containerd Fixed Fixed Fixed Fixed
containerd-app Fixed Fixed Fixed
Show less packages

CVE-2025-47291

Medium priority

Some fixes available 1 of 4

containerd is an open-source container runtime. A bug was found in the containerd's CRI implementation where containerd, starting in version 2.0.1 and prior to version 2.0.5, doesn't put usernamespaced containers under...

2 affected packages

containerd, containerd-app

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
containerd Not affected Not affected Not affected Not affected
containerd-app Not affected Not affected Not affected
Show less packages

CVE-2025-47290

Medium priority
Not affected

containerd is a container runtime. A time-of-check to time-of-use (TOCTOU) vulnerability was found in containerd v2.1.0. While unpacking an image during an image pull, specially crafted container images could arbitrarily modify...

2 affected packages

containerd, containerd-app

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
containerd Not affected Not affected Not affected Not affected
containerd-app Not affected Not affected Not affected
Show less packages

CVE-2025-22872

Medium priority
Needs evaluation

The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly being marked as self-closing,...

7 affected packages

golang-golang-x-net, google-guest-agent, containerd, golang-golang-x-net-dev, adsys...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-golang-x-net Needs evaluation Needs evaluation Not in release Not in release
google-guest-agent Not affected Not affected Not affected Not affected
containerd Needs evaluation Needs evaluation Needs evaluation Needs evaluation
golang-golang-x-net-dev Not in release Not in release Needs evaluation Needs evaluation
adsys Not affected Not affected Not affected
juju-core
lxd Needs evaluation Needs evaluation
Show all 7 packages Show less packages

CVE-2024-40635

Medium priority

Some fixes available 11 of 13

containerd is an open-source container runtime. A bug was found in containerd prior to versions 1.6.38, 1.7.27, and 2.0.4 where containers launched with a User set as a `UID:GID` larger than the maximum 32-bit signed integer can...

2 affected packages

containerd, containerd-app

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
containerd Fixed Fixed Fixed Fixed
containerd-app Fixed Fixed Fixed
Show less packages

CVE-2024-45338

Medium priority

Some fixes available 12 of 15

An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service.

7 affected packages

lxd, adsys, golang-golang-x-net, golang-golang-x-net-dev, juju-core...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lxd Not in release Not in release Not affected Not affected
adsys Fixed Fixed Fixed
golang-golang-x-net Fixed Fixed Not in release
golang-golang-x-net-dev Not in release Not in release Fixed Fixed
juju-core Not in release Not in release Not in release
containerd Not affected Not affected Not affected Not affected
google-guest-agent Not affected Not affected Not affected Not affected
Show all 7 packages Show less packages

CVE-2023-3978

Medium priority
Needs evaluation

Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.

4 affected packages

golang-golang-x-net, google-guest-agent, containerd, golang-golang-x-net-dev

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-golang-x-net Needs evaluation Needs evaluation Not in release Ignored
google-guest-agent Not affected Not affected Not affected Not affected
containerd Not affected Not affected Not affected Not affected
golang-golang-x-net-dev Not in release Not in release Needs evaluation Needs evaluation
Show less packages